Google PCA Design for security and compliance Practice Question
A software company wants to give a third-party analytics vendor read access to a specific BigQuery dataset containing aggregated, non-sensitive sales data, without creating service account keys that the vendor must store and rotate. The security team also wants to be able to revoke access quickly and to see which vendor identities accessed the data. The vendor already uses its own identity provider that supports OpenID Connect. Which TWO approaches together meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is reaching for a service account key as the simplest way to grant external access, when keyless federation plus a narrowly scoped dataset role is the design the scenario is asking for.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the federated principal the BigQuery Data Viewer role on the specific dataset rather than at the project level
Workload Identity Federation removes the need for service account keys by exchanging the vendor's OIDC tokens for short-lived Google credentials, and dataset-level BigQuery Data Viewer grants exactly the read access required. Together they deliver keyless authentication, least-privilege access, fast revocation, and attributable audit records. Static keys and broad project roles fail the security and least-privilege requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant the federated principal the BigQuery Data Viewer role on the specific dataset rather than at the project level
Why this is correct
Granting BigQuery Data Viewer at the dataset level follows least privilege by limiting the vendor to exactly the aggregated dataset they need. Combined with workload identity federation, access can be revoked by deleting the dataset-level binding, and Data Access audit logs will record the federated principal's reads.
- ✓
Configure Workload Identity Federation so the vendor's OIDC provider can exchange tokens for short-lived Google credentials
Why this is correct
Workload Identity Federation lets an external OIDC identity provider exchange its tokens for short-lived Google Cloud credentials, so no service account keys exist to store or rotate. Revoking access is done by removing the IAM binding or the workload identity pool provider, and the vendor's own identity is visible in audit logs.
- ✗
Create a service account with a JSON key and share the key file with the vendor through a secure channel
Why it's wrong here
A downloaded JSON key is a long-lived credential that the vendor must store and rotate, which directly contradicts the requirement. It is also hard to attribute activity to a specific human or workload, and leaked keys are a common breach vector, so this approach fails the stated goals.
- ✗
Enable VPC Service Controls on the project to prevent the vendor from copying the dataset out
Why it's wrong here
VPC Service Controls can restrict data exfiltration across perimeter boundaries, but the vendor is an external identity outside the organization's VPC perimeter. It does not provide keyless authentication and does not by itself grant or scope dataset read access, so it does not address the requirements.
- ✗
Assign the vendor the BigQuery Admin role at the project level to simplify permission management
Why it's wrong here
BigQuery Admin grants broad control over datasets, jobs, and configuration far beyond read access to one dataset, violating least privilege. It also does not eliminate key management, and a broad role makes rapid, precise revocation harder because many permissions are bundled together.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.